Thought Leadership

Are you locking the door but leaving the window open?

Most businesses understand the importance of strong passwords and Multi-Factor Authentication (MFA). They’re often the first things considered when improving cyber security, and rightly so.

But here’s a question worth asking:

Would you feel secure if you locked the front door every night but left the downstairs windows wide open?

Unfortunately, that’s exactly what many organisations are doing when they focus solely on passwords and MFA while overlooking other common security risks.

Strong passwords and MFA remain essential, but cyber criminals are constantly looking for alternative routes into your systems. Protecting your business means securing the whole property.

Strong Passwords Still Matter

Let’s start with the basics.

Weak, reused or shared passwords remain one of the easiest ways for attackers to gain access to business systems. Password attacks are often automated, meaning hackers can try thousands of common password combinations in a matter of seconds.

Good password practices should include:

  • Long, unique passwords for every account
  • Password managers to reduce password reuse
  • Regular reviews
  • Eliminating shared passwords

A strong password remains your first line of defence.

MFA Is Essential But Not a Silver Bullet

MFA adds an extra layer of protection by requiring a second form of verification before access is granted.

This dramatically reduces the risk of account compromise if a password is stolen.

However, modern attackers have become more sophisticated. Phishing attacks, session token theft and social engineering techniques can sometimes bypass MFA if other protections aren’t in place.

Think of MFA as a deadbolt on the door. It’s highly effective, but it works best alongside other security controls.

The Hidden Risk of Generic Accounts

One of the most common security issues we encounter is the use of generic accounts.

Accounts such as:

  • Reception
  • Warehouse
  • Sales
  • Admin
  • Accounts

often have a shared username and password known by multiple employees.

The problem isn’t just security. It’s accountability.

If ten people use the same account:

  • Who accessed the system?
  • Who changed a record?
  • Who downloaded that file?
  • Who sent that email?

The answer is often impossible to determine.

Generic accounts remove audit trails, make investigations more difficult and create unnecessary risk if passwords are shared externally or retained by former employees.

Wherever possible, every user should have their own individual account with appropriate permissions and MFA enforced.

Working Abroad? Is It Really You Logging In?

Flexible working brings obvious benefits, but it also creates new challenges.

When users access business systems from different countries, public Wi-Fi networks, hotels or personal devices, organisations need confidence that:

  • The person signing in is genuinely their employee.
  • The device being used is secure.
  • The connection isn’t presenting unusual risk.

This is where technologies such as Conditional Access and endpoint protection help.

For example, businesses can:

  • Block access from unexpected locations.
  • Require additional verification when sign-ins look suspicious.
  • Restrict access from unmanaged devices.
  • Detect signs of account compromise.

Combined with solutions such as Huntress Managed EDR, businesses gain visibility into suspicious activity and potential threats that passwords and MFA alone cannot protect against.

Unmanaged Devices Create Unmanaged Risk

Many organisations invest heavily in securing Microsoft 365 but pay less attention to the devices connecting to it.

An attacker doesn’t always need to compromise an account if they can compromise the device first.

Questions worth considering include:

  • Are company laptops encrypted?
  • Are security updates being installed promptly?
  • Is anti-malware actively monitored?
  • Can a lost mobile device be remotely secured or wiped?

A secure user account is only part of the picture. The device accessing that account needs protecting too.

How Would You Know If You’ve Been Breached?

This is an uncomfortable question for many businesses.

It’s easy to assume that if nothing appears wrong, everything must be fine.

Unfortunately, cyber attacks are often designed to remain unnoticed for weeks or even months.

Modern threat detection tools monitor for:

  • Unusual logins
  • Suspicious software activity
  • Ransomware behaviour
  • Credential theft attempts
  • Signs of unauthorised access

The sooner suspicious activity is identified, the faster it can be contained.

Security Is About Layers

There is no single security tool that solves every problem.

The most resilient businesses take a layered approach that includes:

✅ Strong passwords
✅ Multi-Factor Authentication
✅ Individual user accounts
✅ Conditional Access policies
✅ Device security and management
✅ Threat detection and response
✅ User awareness training
✅ Reliable backups and recovery processes

Each layer reduces risk. Together, they create a much stronger defence.

Don’t Leave the Window Open

Strong passwords and MFA are an excellent foundation, but they’re only part of the story.

If your business has invested in securing the front door, now might be the time to check the windows too.

At Highstream Solutions, we help organisations identify gaps in their security posture and implement practical protections that reduce risk without getting in the way of day-to-day work.

Because good cyber security isn’t about one control.

It’s about making sure every entry point is protected.